3 часа назад
GRC Program Architect
160 000 - 200 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Program Architect (FedRAMP/CMMC/SOC 2): Designing and implementing Onebrief's compliance framework and technical security controls for defense and government customers with an accent on RMF, federal compliance frameworks, audit readiness, and evidence systems. Focus on translating regulatory requirements into IAM, logging, encryption, vulnerability management, and infrastructure automation that withstand external reviews.
Location: United States, remote
Salary: $160,000–$200,000 per year, plus equity
Company
builds collaboration and AI-powered workflow software for military planning and operational coordination, serving defense and government customers.
What you will do
- Own the design and implementation of the GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
- Build and manage policies, procedures, control environments, and evidence collection systems.
- Implement technical security controls covering access management, logging, encryption, network security, and vulnerability management.
- Partner with Product, Engineering, Infrastructure, and Corporate IT to make compliance controls operational and technically sound.
- Manage customer security questionnaires, compliance inquiries, third-party audits, and assessor relationships.
- Identify control gaps and improve audit and customer security review outcomes.
Requirements
- 5+ years of experience in GRC, security engineering, or a combined compliance and technical security role.
- Direct experience with RMF, FedRAMP, CMMC, or equivalent federal compliance frameworks.
- Hands-on experience implementing IAM, logging and monitoring, network segmentation, encryption, or similar technical controls.
- Working knowledge of NIST 800-53 or NIST 800-171.
- Experience managing third-party audits and assessor relationships.
- Strong written English communication skills and the ability to translate regulatory requirements into clear technical guidance.
Nice to have
- Experience in a startup or scaling company, or a background in military, defense, or government contracting.
- CISSP, CISA, CRISC, AWS Solutions Architect, or another relevant certification.
- Experience with GRC automation, infrastructure-as-code, scripting, GRC platforms, federal cloud security tooling, logging systems, or CI/CD pipelines.
Culture & Benefits
- Remote-first organization with flexible work hours and unlimited PTO.
- Health, dental, vision, and life insurance.
- 401(k) plan with company match.
- Eight weeks of parental leave at 100% regardless of state.
- Annual company retreats and a $1,000 yearly home office budget.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Principal Security GRC Analyst (FedRAMP)
150 000 - 200 000$
4 часа назад
Federal Compliance Lead
130 000 - 170 000$
2 часа назад
Security Governance Risk & Compliance (GRC) Analyst (Cybersecurity)
130 000 - 170 000$
5 часов назад
Compliance Lead (FedRAMP/CMMC)
95 - 140$
5 часов назад
Security Engineer (AWS/Terraform)
220 000 - 260 000$
5 часов назад
Compliance Manager (GovTech)
130 000 - 175 000$